Missing Authorization in Keycloak - CVE-2022-1245
Published: May 4, 2022 / Updated: June 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to an error in the token exchange feature of keycloak. A client application holding a valid access token can exchange tokens for
any target client by passing the client_id of the target. A remote user can bypass authorization process and escalate privileges within the application.
Affected software
Red Hat Single Sign-On
rh-sso7-keycloak (Red Hat package)
How to mitigate CVE-2022-1245
rh-sso7-keycloak (Red Hat package) - addressed in versions 15.0.6-1.redhat_00002.1.el7sso, 15.0.6-1.redhat_00002.1.el8sso